Security Incident Handler
Core
Provide technical escalation and analysis during security incidents to establish threat extent, business impact, and remediation plans.
Role type
Security Incident Handler (SOC)
Builds
Incident response processes and threat detection capabilities
Domain
IT Security / Cyber Operations
Deliverable
client delivery
Required skills
SIEM analysis, network threat analysis, incident triage, MITRE framework, Cyber Kill Chain, alert tuning, Wireshark, Linux administration, security device administration
Preferred skills
ISO27001, NIS2, GDPR compliance, ITIL V4, intrusion detection systems, proxy support, XDR tools (MS Sentinel, ArcSight, Splunk, CrowdStrike, Carbon Black)
Technologies
ServiceNow, MS Sentinel, ArcSight, Splunk, SumoLogic, MS Defender, CrowdStrike, Carbon Black, 7AI, Wireshark
Responsibilities
Analyze events during incidents to identify IoCs and establish mitigation plans; perform quality checks on tickets handled by analysts; provide out-of-hours on-call support; escalate to security support teams; propose alert tuning and suppression strategies.
Seniority
Mid-level, hands-on IC